The sweep (main's item 1): 199 tracked text files, 783 lines. The founder's full name, first name and possessive become "the founder" (sentence starts capitalised); the lowercase operating-system user name in WSL paths and commands becomes <user>; the second owner login becomes "the second owner login"; the three earlier businesses and the two other brands become "the other business", "the earlier entity", "the earlier business" and "another brand"; the Chrome profile rule names the igneum.network profile, not the profile's label. The standing commit login igneum-labs is not a founder term here: the fresh-repository step renames it in the history (docs/plans/history-rewrite.md, tools/repo/fresh-repo.sh). The patterns never appear in plain text in the tree (a plaintext list would be the hit): tools/ci/founder-strings.b64 (perl regex, tab, a sample per row) is read by tools/ci/founder-strings-check.sh (every tracked text file, perl, known-failed first: the self-test plants each row's sample in a fixture and the hit must name the file), by tools/community/discord-hooks.mjs (the guard's founder and business rows; the test takes its fixtures from the samples) and by tools/repo/fresh-repo.sh (the business names of the rewrite rules). site/forbidden-strings.txt carries the same patterns as b64: lines, decoded case-insensitive by site/scrub.mjs and tools/ci/launch-gates-check.mjs (whose fixture now plants an encoded made-up name). The check runs in the gate's tree checks on every merge. Not in this commit, by main's word: the 105 commit messages and 40 personal-identity commits that need the history rewrite (listed, not run), and the secrets found by gitleaks over the history (reported with owners). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
64 KiB
Igneum FUD fixes
Internal working list. Written 3 October 2026 against docs/fud-ledger.md version 0.1, docs/spec/06-open-items.md, docs/bench-log.md, and the public text in site/index.html (HP), site/litepaper.html (LP) and site/journey.json (J) as checked this evening. The ledger itself is not changed by this file. Entries are referenced by ledger id; overclaims by item number.
Decisions of 3 October 2026 applied throughout: (a) no development fund, priority fee 80% to miners and provers and 20% to the called app, external jobs 90% to provers and 10% burned; (b) the ledger is internal (superseded 5 October 2026: the ledger is published with the repository at the public testnet); (c) the project is established offshore and the founder's location is never mentioned; (d) deSEC nameservers now, a non-US registrar in December 2026; (e) the dedicated identities exist (GitHub organisation igneum-network with one anonymous owner, Vercel team igneum, Google Workspace on igneum.network).
1. Summary
- The ledger holds 80 entries and 78 overclaim items. Every entry appears once below: 64 open or conceded entries across 74 rows in section 2, and 16 answered entries that still carry a fix in section 2.1.
- Open: 11 entries after the evening closures of 3 October 2026 (F2, F3, P5, P8, C9, E7, G7, X6 closed by rule or decided; section 4). 7 close on a measurement, 4 on counsel or a search (L1, L2, L4, L5).
- Conceded: 45 entries. 13 are already stated in public text, 32 are not.
- Answered: 16 entries. All 16 still carry a wording fix, an experiment or a counsel check.
- Overclaims: 78 items. 10 already fixed (5, 6, 9, 22, 23, 27, 38, 40, 47, 71), 3 partly fixed (11, 31, 75), 65 still present or still missing. Item 23 is fixed but stale. Item 73 must not be applied as written.
- The 3 October decisions close E4 outright, narrow G4, G8 and L3, and change E3, E5, G3 and G5 (section 4). The dev fund removal forces a rewrite of 11 places in the site, spec and design files (row 7).
- EXPOSES: six items. CLAUDE.md (full name, other companies, registrar, database region, personal GitHub handle), the cryptographer agent file, the commit handle igneum-labs, the local-time offset on every commit, the earlier ledger text "The founder is in the UK" still in git history, and the ledger itself in the tree. All are fixed in section 5.
- Measured since the ledger was written: the 256 MB cache dataset is built and bit-exact on Apple, NVIDIA (CUDA and OpenCL) and an AMD integrated chip; the shortcut is 4.8x slower than honest on Apple; CPU verify is 0.41 to 1.2 ms per warp with the cache; the VDF grinding simulation ran. Items 16, 20, 21, 23, 56 and 78 need these facts, not the ledger's replacements.
- By timing: 44 rows now (site text, decisions, accounts; two of them continue into December and mainnet), 12 before the repository goes public (citations, counsel, gate 1 measurements, the phase 2 benchmark), 16 before public testnet (gate 2 and 3 work, policies), 1 before mainnet, 1 with nothing further (F6).
- Five most urgent: section 5 steps 1 to 4 (the tree and history must be clean before any public push); rows 1 to 5 (dead links, the miner button, no contact route, listings, Day one); row 7 (dev fund text everywhere); row 9 (the founder is pseudonymous now, the text and the ledger disagree); rows 43 to 46 (trademark and counsel).
2. Every open or conceded entry
Who: the founder (decision or account), Claude (text, spec, code, simulation), counsel, measurement (an experiment that produces a number). When: now, before public repo (opens at the public testnet, August 2027), before testnet (August 2027), before mainnet (November 2027).
| # | Ledger | Issue | Fix | Who | When | EXPOSES |
|---|---|---|---|---|---|---|
| 1 | X1 | HP footer, HP nav and the /bench page link to a private GitHub repository | Remove the GitHub links (site/index.html line 422, the nav in site/build.mjs) until the repository is public; put them back on the day | Claude | now | no |
| 2 | X2 | "Get the miner" three times and "Start mining" on HP with no miner | Item 60: "Benchmark: January 2027", linking to #journey | Claude | now | no |
| 3 | X7 | No contact route on HP or LP | the founder creates a mailbox on the igneum.network Workspace; Claude adds it to the HP footer and the LP cover (item 77). No public ledger route is needed now the ledger is internal | the founder, then Claude | now | no |
| 4 | X8 | "exchange listings after" in the LP roadmap (line 422) and J phase 6 | Item 58 in both files | Claude | now | no |
| 5 | X10 | Eleven log entries, all dated 3 October 2026 | Add a "Day one" label above the log in site/index.html | Claude | now | no |
| 6 | L2 (with E2) | Inducement wording: "so the people who show up early get the most" (LP 183), chart caption "Half of the 4 billion cap is mined in the first two years" (LP 184), HP "Half of all IGN is mined in the first two years" | Items 54 and 76: schedule facts, no "so" clause. Counsel opinion is row 46 | Claude | now | no |
| 7 | E4, E5, G5, G8, O-5.4 | Dev fund text everywhere after decision (a): LP Economics (65/15/15/5 paragraph, "Development, paid by outsiders" section), LP Governance (fund bullet, second-client bullet), LP firsts row ("a development fund paid by outsiders"), HP Economics ("Development is paid from fees..."), spec 05 sections 5.2, 5.4, 5.5 and the self-dealing arithmetic, spec README row 5, spec 00 row 5, spec 06 items O-5.4 and O-5.7, docs/design/execution-layer.md lines 143, 210 and 217, the design document (CLAUDE.md already carries the new split) | Rewrite to: base fee burned in full; priority fee 80% miner and provers, 20% called app; external jobs 90% prover, 10% burn; no fund. The founder confirms the 15% priority-fee burn is gone on purpose (section 4) | Claude, the founder confirms | now | no |
| 8 | E5 | HP "Not one coin to a founder, a fund or a stake" while the official client carries a 1% dev fee to the founder's company; LP spreads the dev fee, the pool and the proving business over three sections | Item 62 on HP. One LP heading that holds the 1% dev fee, the pool, the proving business, and that these now fund development since there is no fund | Claude | now | EXPOSES: "the founder's company" must be the offshore entity once it exists, never a company the founder already owns |
| 9 | G3 | The ledger's answer says "The founder's name is on every commit". Decisions (c) and (e) make the founder pseudonymous | Do not apply item 73 as written. LP "Who are you?" gets: "The founder is pseudonymous until the team page at public testnet. No cryptographer is hired yet." Decided 5 October 2026: no team page for now; the litepaper says the team is pseudonymous and names no team page | the founder decides, Claude writes | now | EXPOSES: the ledger answer and CLAUDE.md name the founder; see section 5 |
| 10 | F5 | "whole network's hashrate" misread | Item 32 | Claude | now | no |
| 11 | F10, F4, G8 | Pool concentration unstated; LP heading "Speed and finality, powered by miners alone" | Items 33 and 43. Heading becomes "Speed and finality, a miner-weighted overlay on proof of work". Name pool concentration as the governance risk | Claude | now | no |
| 12 | C3, M3, C8, C11 | Kaspa misstated; firsts table; LP 68 "taken over by chips, as Kaspa was" still reads as capture; Conflux missing from the problem section | Apply items 4, 7, 8, 10, 11 and 29. Items 5, 6, 9 and 47 are done | Claude | now | no |
| 13 | C5 | Inclusion compared to finality | Item 30 without the "see the FUD ledger" cross-reference | Claude | now | no |
| 14 | C2, M1 | Chip claims: "no chip can ever", "nothing for a chip to be built for", "same margin that has protected Monero for seven years", "runs for ever ... with no chip built" | Items 1, 2, 13, 17, 18, 19, 50, 59, 63, 67, plus the HP Mine card line "nothing for a chip to be built for" | Claude | now | no |
| 15 | M10 | "bound by memory bandwidth" | Item 14 with the 5090 numbers (95 GB/s useful against 1,638 GB/s sequential) | Claude | now | no |
| 16 | M5 | "memory footprint and instruction count are fixed" while loads vary 40 to 232 | Item 15 | Claude | now | no |
| 17 | M2, M9 | Items 16, 21, 23 and the first item of 78 were written before the cache landed. Bench log 3 Oct: memory-hard dataset built, bit-exact on Apple, NVIDIA and AMD integrated; shortcut 4.8x slower on Apple (closed form was 111x faster); CPU verify 0.41 to 1.2 ms per warp with the cache on one M5 Max core | Rewrite items 16, 21, 23 and 78 with the new facts: shortcut closed on Apple, NVIDIA and AMD ratios pending; 10 ms gate met on one core, a 2019-class core pending | Claude | now | no |
| 18 | M8 | "Any card, any vendor. Bit-exact on Apple and NVIDIA" (LP 126, HP 64); "NVIDIA and AMD both work" (LP 224) | Items 20, 56 and 66 updated: bit-exact on Apple Metal, NVIDIA CUDA and OpenCL, Apple OpenCL and an AMD integrated chip; discrete AMD and Intel not yet run | Claude | now | no |
| 19 | M13 | "Macs mine too" without the ratio | Add "at about a fifth of a flagship card; the app shows projected earnings before it starts" | Claude | now | no |
| 20 | P2 | Launch gas budget unstated | Publish the launch budget as a formula: cards proving times shards per card per minute | Claude | now | no |
| 21 | P3 | "a phone can check it in milliseconds" | Item 25 | Claude | now | no |
| 22 | P4 | "Trustless light clients ... need no multisig" (LP 171) | Item 38 (item 9 is done) | Claude | now | no |
| 23 | P5 | "runs on Igneum unchanged" (abstract and LP 168); "Three things run on Igneum that run nowhere else" | Items 35 and 36, plus the abstract sentence; the documented differences now exist in spec 7.1 (P5 closed 3 October 2026), so the replacement can point at them | Claude | now | no |
| 24 | P6, C10 | "cheapest supplier", "lowest cost", "last provers to switch off" (LP 73, 222, 277, 293) | Items 12, 49 and 55, plus the "guaranteed income floor" paragraph | Claude | now | no |
| 25 | P7 | "a block with a wrong state cannot exist"; "Nothing in it ever needs a human" | Items 3 and 26 | Claude | now | no |
| 26 | P10, E7 | Economics says outsiders pay in IGN and part is burned; the miner section says they pay in their own money; "Stablecoins at genesis ... through the proof bridge" (LP 176, 284) | Items 40 and 71 applied 3 October 2026 (E7 decided, spec 7.3); item 52 (the P10 contradiction in Economics) still open | Claude | now | no |
| 27 | E1, E6 | Supply states the cap, not the tail-emission trade-off; halvings presented as fact, not a bet | Two sentences in Supply: the tail alternative and why the cap was chosen; the halving schedule is a bet, a tail can be added by 90% signalling | Claude | now | no |
| 28 | G1 | "named reviewers" who do not exist; "The specification is public" (LP 271) | Items 48 and the third item of 78 | Claude | now | no |
| 29 | G2 | Method undisclosed | Item 72. Keep the Co-Authored-By trailers in the history: they are the evidence the entry cites | Claude; the founder confirms the trailers stay | now | no |
| 30 | G4 | "There are no admin keys" (LP 236), "0 admin keys" (HP) | Item 45 minus the fund contract; HP tile becomes "0 admin keys in consensus" | Claude | now | no |
| 31 | G5 | "second independent node client, funded from the development fund" (LP 237) | Item 46 rewritten: "At launch there is one node client. A second independent client is not in the 13-month plan." The funder is row 47 | Claude | now | no |
| 32 | G6 | "Pools cannot censor" (LP 235) | Item 44 | Claude | now | no |
| 33 | C1, C12 | "Monero's idea, finished for GPUs" (LP 119, HP 57) | Item 68 in both | Claude | now | no |
| 34 | C6, X4 | Roadmap does not say the combination is the risk; "Dates slip. Gates do not." missing | Item 69 plus one sentence: each piece has a precedent, the combination has none, and that is what the gates price | Claude | now | no |
| 35 | C7 | New miners vote after a month, unstated | One sentence in Finality: a new miner's vote reaches full weight after a month; its rewards do not wait | Claude | now | no |
| 36 | F1, X9 | First month: Finality has the thin-weights sentence (item 31 partly done); "Fair launch" and "What Igneum does not claim" do not; "exchanges are told to treat it so" missing; "no amount of fresh hashrate" remains | Finish item 31; apply item 75 and the second item of 78 | Claude | now | no |
| 37 | F8 | Day counts quoted as facts | Item 74 | Claude | now | no |
| 38 | F2 | The two-hour window's exposure unstated | Item 34; the source text is now spec 3.3.2 (F2 closed by the floor, 3 October 2026) | Claude | now | no |
| 39 | X3 | "All of it will be on this page, live" with no date | Item 61 | Claude | now | no |
| 40 | F12 | "Nothing in Igneum's consensus depends on anything outside Igneum" (LP 166) | Scope to "no other chain's state"; name the code dependencies (SP1, BLS12-381, class-group VDF, rusty-kaspa) in one line | Claude | now | no |
| 41 | F13 | Why prove if every node executes: unstated | One sentence under the 20% row: the share pays a standing prover population, and the proof serves light clients, bridges and sync from a proven checkpoint | Claude | now | no |
| 42 | F6 | Equivocation costs history, not coins | Stated (LP 164, design doc). Nothing further | none | no | |
| 43 | L5 | No trademark search recorded | Search EUIPO, USPTO and UK IPO in classes 9, 36 and 42; record the result outside the repo; the name stays provisional until then | the founder, counsel if a hit | now | EXPOSES: any application comes from the offshore entity, never from the founder or a company he already owns |
| 44 | L3 | US registrar, US nameservers, US host | Now: deSEC nameservers (in progress); recreate the Vercel records at deSEC and re-verify every domain in the Vercel project. December 2026: non-US registrar when the transfer lock ends. Before mainnet: IPFS mirror, ENS or equivalent name, site content hash in the repo and in genesis, seed nodes as addresses in the client | the founder (accounts), Claude (mirror, hashes) | now, December, before mainnet | EXPOSES: the ledger and CLAUDE.md name the registrar and the host; keep both out of the public tree |
| 45 | E8 | Founders seed the DEX | Stated. Whether to do it at all goes to counsel in row 46 | counsel | before public repo | no |
| 46 | L1, L2 | Howey and promotions: founder business, founder-seeded DEX, launch grants, listings (row 4 removes listings) | Counsel in the entity's jurisdiction reviews the founder-business paragraph and the promotions question before litepaper v0.2. The ledger's "offshore, parked" becomes "offshore, being established". The founder decides whether igneum.co.uk stays in the redirect set (a weak UK hint; WHOIS is redacted) | counsel, the founder briefs | before public repo | EXPOSES: the brief names the entity's jurisdiction, never the founder's residence |
| 47 | G5 | The second client has no funder now the fund is gone | Decide: the operating company, a grant from the proving business, or not in the plan | the founder | now (decision), before mainnet (client) | no |
| 48 | M4 | Firsts row is done (item 5); ProgPoW and Ravencoin are cited nowhere | Clone the ProgPoW specification and the Ravencoin repository into vendor/; cite path and commit in the spec | Claude | before public repo | no |
| 49 | C8, C3 | Ergo, Ravencoin, Conflux and rusty-kaspa claims are from memory | Cite each from its repository; label approximate until then | Claude | before public repo | no |
| 50 | M1 | ASIC gain under 2x is a target | Public benchmark, leaderboard by card model and a standing bounty with the January 2027 release (O-1.17). Bounty terms and funding are the founder's | the founder (terms), Claude (benchmark), measurement | before public repo | EXPOSES: the bounty payer and terms carry the entity, not the founder |
| 51 | M5 | Load count varies 6x | O-1.2: exact 16 load positions in the generator, re-fuzz 10,000 programs, confirm the loads-per-hash column is constant | measurement | before public repo | no |
| 52 | M6 | Weak programs unmeasured | O-1.3: census of at least 10^5 programs and a rejection rule in the generator | measurement | before public repo | no |
| 53 | M7 | Ad hoc seed derivation, no analysis | O-1.1: standard hash into the seed words, new vectors. O-1.4: external review scoped to the fair-lottery properties | Claude (code), then review | before public repo | no |
| 54 | M8 | Discrete AMD and Intel never run; the fuzz set has run on Metal and the CPU only | O-1.15: the proto-opencl commands on a discrete AMD card; the 10,200-program fuzz and the 14 edge programs on NVIDIA and AMD; Intel Arc after | measurement | before public repo | no |
| 55 | M2 | Shortcut ratio measured on Apple only | O-1.5: inline kernel on the 5090 and a discrete AMD card. O-1.6: the time-memory curve and the hoisting attacker | measurement | before public repo | no |
| 56 | M9 | Verify gate measured on one M5 Max core | O-1.14: the Rust verifier on a 2019-class laptop core at 104 and 144 loads | measurement | before public repo | no |
| 57 | P1, P3 | No SP1 shard proven on any card; wrapper cost unknown | Phase 2 benchmark: shard time on a 3060-class card and the wrapper cost on consumer hardware, published with the January 2027 release | measurement | before public repo | no |
| 58 | L4 | Paying testnet miners needs an entity, terms and tax treatment | Entity first (decision c); counsel writes the terms before phase 5 | counsel | before testnet | no |
| 59 | L6 | Dollar-paid job market read as money transmission | Counsel confirms the no-custody structure before phase 4 | counsel | before testnet | no |
| 60 | M11 | Hourly compile on real rigs unmeasured | O-1.16: miner client prototype on a multi-card rig; compile time and failure rate per hour | measurement | before testnet | no |
| 61 | F1 | No weight in the first month | O-3.1: launch-month simulation; decide the no-certificate-for-30-days rule; the litepaper states it either way | Claude (sim), the founder (decision) | before testnet | no |
| 62 | F3 | Participation grinding through the bitmap | Closed by rule 3 October 2026: spec 3.3 Q2 and 3.4.1, participation from every vote seen in blocks. Remaining: O-3.3, the per-block vote bound and the re-run under the block reading | Claude (sim) | before testnet | no |
| 63 | F7 | Checkpoint depth 60 is a placeholder | O-3.2: devnet with regional latency, reorg-depth distribution per block rate | measurement | before testnet | no |
| 64 | F2 | Presence window as an eclipse vector | Closed by rule 3 October 2026: spec 3.3.2, the 56.7% floor. Remaining: O-3.7, the devnet single-node eclipse as confirmation; no rule choice | measurement | before testnet | no |
| 65 | C4 | The overlay changes GHOSTDAG's guarantees | O-3.8: devnet runs with the module on and off; adversary simulation from real pool-hashrate traces | measurement | before testnet | no |
| 66 | P8, C9 | First-come shards centralise | Closed by rule 3 October 2026: spec 7.2, sortition to 8 provers for 10 s then open, no shard bond. Remaining: O-5.1, the parameters on the phase 4 devnet | measurement | before testnet | no |
| 67 | P5 | EVM semantics on a DAG | Closed by spec 3 October 2026: spec 7.1 (number, timestamp and its monotonicity rule, blockhash, PREVRANDAO from the epoch VDF, coinbase, gas limit, chain id, quoted gas price); O-2.8 removed | done | done | no |
| 68 | P7 | Soundness-bug handling | Spec rule: a full node rejects a proof whose state root differs from its own execution; the proof-system version has a stated human emergency path | Claude | before testnet | no |
| 69 | P9 | Shard bond and timeout open | O-5.6 on the phase 4 devnet | measurement | before testnet | no |
| 70 | E7, P10 | Genesis bridge trust model undecided | Decided 3 October 2026: spec 7.3, no bridged stablecoins at genesis, no official bridge, proof bridge with the consensus proof in phase two; LP and HP text changed. Remaining: O-5.2, how the IGN settlement switch is activated | done (the founder); Claude for O-5.2 | before testnet | no |
| 71 | G1 | No cryptographer; no named reviewers | Contract a cryptographer for phases 1 and 2; name and pay external reviewers before gate 3 | the founder | before testnet | EXPOSES: contracts come from the entity; reviewers are told the founder is pseudonymous |
| 72 | G7, X6 | The update channel is a key; the installer is a honeypot vector | Decided 3 October 2026: spec 08-client-security.md (reproducible builds, release key in genesis and in hardware, no silent updates, consensus only by 90% signalling, notarised builds, official sources with the hash, seed confirmed before mining, hardware wallet, the permanent line). The line is on HP and LP. Remaining: O-8.1, the key custody policy and toolchain publication | the founder (key custody) | before testnet | no |
| 73 | X5 | "1,000 independent miners" is a Sybil number | Define independence measurably (distinct ASNs, benchmark hardware fingerprints, pool attestations) before the gate is tested | Claude drafts, the founder decides | before testnet | no |
| 74 | G4 | Genesis contract and bridge key policies | Publish each genesis contract's key policy before launch (O-5.4 without the fund contract) | Claude, the founder | before mainnet | no |
2.1 Answered entries that still carry something
| Ledger | What remains | Row |
|---|---|---|
| M3 | Items 11 and 49 wording | 12 |
| M8 | AMD discrete and Intel; fuzz set on NVIDIA and AMD | 18, 54 |
| M10 | Item 14 wording | 15 |
| M12 | The lottery half is conceded; covered by the first-month rule | 36, 61 |
| F4 | Call it an overlay on proof of work | 11 |
| F9 | The gate 3 experiments decide the denominator rule | 64 |
| F11 | The grinding simulation ran (proto-vdf: +3.62 blocks per epoch at 30% without the delay, 0 with it). Left: O-4.9 re-run with the census distribution; O-4.1 second cryptographer reads classgroup.rs against chiavdf | 52, 71 |
| F12 | Scope the "nothing outside" sentence | 40 |
| F13 | Say what the 20% buys | 41 |
| P9 | Bond and timeout | 69 |
| E2 | Inducement wording and counsel | 6, 46 |
| E3 | The arithmetic changes with the new split; see section 4 | 7 |
| E4 | Closed by decision (a) | 7 |
| C1, C12 | Item 68 | 33 |
| L6 | Counsel before phase 4 | 59 |
2.2 Round 3 entries (3 October 2026, evening)
Added after docs/review/round-3-2026-10-03.md. Rows continue the numbering of section 2. "code, owner consensus engineer" marks a row that needs node code and is not Claude's text work; the ledger status for those stays as the review left it.
| # | Ledger | Issue | Fix | Who | When | EXPOSES |
|---|---|---|---|---|---|---|
| 75 | F18 | LP Finality: "a silent minority cannot freeze finality and a lock never waits for miners who have left" | Fixed 3 October 2026: the exchange engineer's replacement sentence in LP Finality; "Finality that never pauses" item added to "What Igneum does not claim" | Claude | done | no |
| 76 | P13 | LP Proving: "Miners claim shards with a small bond" | Fixed 3 October 2026: "Shards are assigned by lot to eight provers for ten seconds, then open to anyone; there is no bond" | Claude | done | no |
| 77 | E11 | HP tile "IGN burned from jobs, at launch"; the quoted paragraph had already left the trimmed page | Fixed 3 October 2026: tile reads "phase two"; caption adds "Jobs are paid on the customer's chain at launch; settlement in IGN with a 10% burn follows the proof bridge in phase two" | Claude | done | no |
| 78 | L7 | LP Economics heading "Where the price comes from" and the burn-reduces-supply sentence | Fixed 3 October 2026: heading "Where fees go", sentence deleted. Counsel reads the section under row 46 | Claude; counsel | done; before public repo | no |
| 79 | P11 | Native-execution veto written against the node's current selected chain | Spec 7.2 item 5 rewritten 3 October 2026, relative to the carrying block's own selected-parent chain. docs/design/execution-layer.md 5.5 and D12 rewritten and the two-node reorg test added to its 8.5 the same evening |
Claude | done | no |
| 80 | F17, P8 | Shard sortition per key; keys are free; launcher mints 8 per card | Spec 7.2 step 2 draws by weight and spec 3.1 W6 states the principle, 3 October 2026. Left: client default of one vote key per operator (MINERS multiplies workers, not keys); S2 and the bitmap size (O-3.5, O-3.12) before the voter count can cross 8,192 |
Claude (spec, done); miner client (default) | before testnet | no |
| 81 | M14, F14 | Weight and presence windows in DAA seconds under a lagging retarget; no finality run with a DAA model | Spec 3.1 W2 and 3.3 Q1 in past-median time, weight per 60-s bucket, 3 October 2026 (simulated form kept beside it). O-3.14 added: finality_v2.py with the DAA in the loop, 50x pulsed renter, both W2 forms, logged in the bench-log. Controller choice is gate 2 (O-2.1) |
Claude (spec, done); measurement (O-3.14) | before testnet | no |
| 82 | F15 | Merge depth called the reorg bound; the code's bound is the finality depth, 43,200 DAA s | Spec 2.1, 3.8 and 3.9 name the finality depth, in median time (12 h), 3 October 2026; simnet reorg test (2, 6, 13 h forks) written into 2.1 for gate 2. LP Finality (first-month and merge-depth sentences) and "What Igneum does not claim" item 4 rewritten the same evening: 12-hour finality depth, merge depth a merge limit. Left: the simnet test | Claude (done); measurement (simnet) | before testnet | no |
| 83 | E9 | Spec year 365 days; code 365.25 (31,557,600 s, halving 63,115,200 s, 3,168,808,781 sompi/s) | Spec 2.5 follows the code, 3 October 2026. Divergence record for the code owner: the spec was changed, the code was not; add a test that reads the published numbers (year, halving interval, per-second rate, ramp) and asserts them against consensus/core/src/igneum.rs, and decide O-2.6 (8 decimals fits the u64 cap, 18 does not) before the first testnet genesis |
code, owner consensus engineer | before testnet | no |
| 84 | E10 | Spec said reds unpaid and "more blocks never means more coins"; code pays reds in the DAA window to the merger and mints per block | Spec 2.5 follows the code, 3 October 2026. Divergence record for the code owner: no code change; the litepaper Speed sentence ("never per block") was rewritten the same evening to match 2.5: emission per block on a schedule keyed to difficulty-adjusted time, reds in the window paid, coins track blocks within the controller's accuracy | Claude | done | no |
| 85 | G9 | Release key: single steward, lost key unrevocable | Spec 8.2 items 2 and 5 rewritten 3 October 2026: key chain, rotation signed by the current key, revocation signed by the previous key (pre-signed certificate for K0), published in a block; policy before the client ships, with entity and jurisdiction. Left: the policy itself and the second holder (O-8.1, L1) | the founder (custody), counsel | before testnet | EXPOSES: the policy names the entity, never a person's residence |
| 86 | M15 | Pre-validation PoW cost: any past timestamp or claimed DAA score forces a 256 MiB cache fill before the checks that would reject the header | Run check_difficulty_and_daa_score and the past-median check before check_pow_and_calc_block_level in validate_header; derive the day from DAA score or the selected parent's window; KEEP 4; per-peer cap on cache builds. Review's first of five |
code, owner consensus engineer | now | no |
| 87 | M20 | Pruning proofs validated with the kHeavyHash stub: a fresh node cannot sync from a lottery-mined pruning point; a loosened check is forgeable with an existing ASIC | Thread the epoch and day seeds through pruning_proof/validate.rs, apply.rs and mod.rs (fork map a4, O-2.5); test by syncing a fresh node from the 30-hour devnet |
code, owner consensus engineer | before testnet | no |
| 88 | P12 | An aggregator rewrites ProofRecord.provers and takes the pool; shard proofs do not commit to the prover |
Shard statement gains the prover's payout key as a public input, aggregation carries the keys as public outputs, a record whose list does not match is invalid; acceptance test A5 checks the match. Spec 7 and docs/design/execution-layer.md 5.1, 5.6 and 9.2 change with the code |
code, owner consensus engineer (with execution engineer) | before testnet | no |
Not yet rowed from round 3: M16, M17, M18, M19, M21, F16, P14, P15, C13, L8, G10, X12. Their fixes are in the ledger entries.
2.3 External review entries (3 October 2026, night)
Added after docs/review/external-2026-10-03.md. Rows continue the numbering of section 2.2.
| # | Ledger | Issue | Fix | Who | When | EXPOSES |
|---|---|---|---|---|---|---|
| 89 | P16 | Phase 2 gate passable by shrinking the shard (design R2's fallback); no end-to-end standard | J phase 2 gate rewritten 3 October 2026 (night): fixed workload, job received to accepted proof, no growing backlog, three independent reproductions. Left: O-7.1, the benchmark itself; R2's fallback sentence to say a halved shard is a new declared workload, never a pass | Claude (J, done); measurement | before public repo | no |
| 90 | F19 | Bought, borrowed or stolen vote keys carry 30 days of weight; only renters are modelled | O-3.15: finality_v2.py key-transfer scenario against the same share as fresh hashrate, with the 40/40/20 row; decide W5 re-earning and weight decay |
Claude (sim), cryptographer | before testnet | no |
| 91 | F20 | No statement of what holds during a finality pause; the seed pipeline from uncertified checkpoints is a proposal (O-4.3) | O-3.16: decide O-4.3, write the four pause guarantees into spec 3.7, devnet stall through 3 epoch boundaries | Claude (spec), measurement | before testnet | no |
| 92 | P17 | Three states shown; included is a list | Design 2.4 written 3 October 2026 (night). Left: state field in igneum_getTransactionStatus, the phone-app and explorer words, the O-7.2 conformance set |
Claude (design, done); code, owner execution engineer | before testnet | no |
| 93 | E12 | No stress test of mining against proving under shocks; R8 has not run | O-5.9: R8 extended with 10x external pay, falling price, operator exit, unfulfilled assignments, profit-only clients; then the phase 4 devnet | Claude (sim), measurement | before testnet | no |
| 94 | E13 | No payment-route diagram; the routes are spread over LP Economics, the HP tiles and the customer brief | O-5.10: one figure, one route per row (emission, base fee, priority fee, jobs at launch, jobs after the bridge, client dev fee), in LP Economics and the brief; operator revenue never summed with protocol revenue | Claude | now | no |
| 95 | E14 | No funding table | Cost lines against sources, labelled funded / dependent on revenue / unfunded, with the late-revenue case; internal until counsel reads it; unfunded lines stated in LP | the founder (numbers), Claude (table) | before public repo | EXPOSES: sources name the entity, never a company the founder already owns |
| 96 | E15 | Security budget through halvings with low fees, no demand and a flat price: unmodelled | O-5.11 model; the failing year and price stated in LP Supply next to the tail alternative (row 27) | Claude (model) | before mainnet | no |
| 97 | G11 | Repository private; harnesses, vectors, simulators and spec could be public now, labelled experimental | the founder decides the components, licence and date; section 5 steps 1 to 7 first in any case; one proof-request workflow and one reference app before any app set | the founder | now (decision) | no |
| 98 | X13 | Phase 4 gate is a signature; the brief says no payment | Brief v0.2: agree workload, proof format, deadline, failure rate and price before the pilot; publish the outcome and the customer's reason; paid pilot added to the J phase 5 line; entity and terms per L4; timing is the founder's | Claude (brief), the founder, counsel | before testnet | no |
| 99 | X14 | Independence undefined; concentration in hashing, signing, proving and aggregation unreported | O-X.1: define independence; four concentrations as top-1, top-3 and top-10 shares over 30 days on the live page beside the gate | Claude (observer), the founder (definition) | before testnet | no |
| 100 | X15 | "The chain runs without its founders" untested | O-X.2: 24-h founder shutdown on the public testnet at a published time; record what continues | measurement | before mainnet | no |
| 101 | X16 | No evidence page; one voice for implemented, team-tested, reproduced and reviewed | O-X.3: one row per public claim with status, version, test, result and one of the four labels; audits tied to versions; ships with the benchmark | Claude | before public repo | no |
| 102 | X17 | Client shows gross earnings only; no mining and proving split, no failed jobs, no isolation design | O-8.2 display rules (client and phone-app 4.1, written 3 October 2026 night); O-8.3 isolation design before the first external job; update control already spec 8.2 item 4 | Claude (design); miner client (code) | before testnet | no |
| 103 | M22 | Bounty has no metric, judge, eligible hardware or fund; 2x is not the economic line | Scoring rules (per-program distribution of hash/s and hash/J, capital per unit of hash rate, longevity, shortcut classes) published with the benchmark; funder, judge and reward are the founder's; public claim limited to "competitive against the best independently proposed design across tested workloads" | Claude (rules), the founder (fund) | before public repo | EXPOSES: the payer is the entity (row 50) |
2.6 Sweep (5 October 2026, evening), round 6: the experiment and status items
Appended by the consensus engineer and cryptographer agent (worktree igneum-wt-fud-a); the wording items of the same evening are the other agent's section. Rows below name the earlier row they touch; nothing above is rewritten. Evidence in docs/bench-log.md, "5 October 2026 (evening), FUD ledger sweep round 6".
| Row touched | Ledger | What changed (5 October 2026, evening) | Who next | When |
|---|---|---|---|---|
| 106 | G12, X18 | Done and rolled out (0.3.5, 07:33 BST; every node prints the digest, the digest refused the early-restarted hand node for 20 min at 08:15 BST). Left: the digest-less allowance on devnet and simnet, rollout-v2.sh two-field write |
consensus engineer | before testnet |
| 107 | F23, F24 | Done and rolled out (0.3.5): 0 "names N voters" refusals and 0 CONFLICTING on five machines in 10 h; checkpoints 2970 and 2971 re-determined on three machines at 10:56 BST with no hole | none | done |
| 108 | M26, M27, X21 | Done and rolled out (0.3.5): the 0.3.4 prepare storm (4,299 refusals in 2 h on PC 1) ended at the 0.3.5 start, 0 prepare-failed since; cards read mismatched=0 faults=0. Left: the edited-kernel red-card test on a PC |
miner lead | when convenient |
| 117 | M20 | Done and rolled out (0.3.5, m20-pruning, 4 tests). Left: the live test, a fresh node syncing once the pruning point leaves genesis (still genesis at DAA 113,289 at 16:00 UTC) |
consensus engineer | tonight or tomorrow, when the point moves |
| 2.5 (M30, "the flood memory growth") | M30 | Done and rolled out (0.3.5): cache builds equal node restarts (5 / 5 / 8 in 10 h), none at the epoch rolls | none | done |
| (F25) | F25 | Done and rolled out (0.3.5 merge 7abce72); both harness libraries ran tonight | none | done |
| (F21, F22) | F21, F22 | Shipped in every node since 0.3.4; the switch finality_v3_activation_daa is absent from the live override file. Rollout = N3 of docs/plans/finality-v3-rollout-devnet.md |
the founder (N3), then the operator steps | now |
| 50 | M1 | Program space counted (about 2^1550 shapes under a 2^256 seed; the per-program spread is 1.10x under version 2). The claim stays a target; the experiment stays the bounty and benchmark | the founder (M22 terms), Claude (benchmark) | before public repo |
| 60 | M11 | Measured on five machines, four compilers, three vendors over 10 to 12 boundaries each: NVRTC 0.6 to 1.1 s, OpenCL 7 to 12 s (iGPU 55 to 124 s beside builds), Metal under 0.5 s plus the race; 5090 race +0.00%, base twice. Left: multi-card rig, ROCm (hardware) | measurement (O-1.16) | before testnet |
| 55 | M16 | Cost model written (docs/analysis/m16-recompute-attacker-2026-10-05.md): 1.5x to 2.4x at equal integer budget, 3x to 6x with a fixed-function factor, the mixer-cost lever. Left: the 64 MiB-cache inline kernel on the 5090 (PC job), O-1.6 |
measurement; the founder at gate 1 | before public repo |
| 121 | M21 | Block sizes measured (p50 723 B, max 6.9 KB); k 5 at the measured p99, 6 with 500 KB bodies, 18 at 5 s. Left: O-2.2 with proof-bearing bodies | consensus engineer | before testnet |
| 57 | P3 | The certificate half measured in a phone-sized tab (139 to 155 ms cold, 58 to 68 ms warm, on the laptop's CPU; no phone); the wrapper is unbuilt | measurement (phase 2) | before public repo |
| 69 | P9 | Parameter table written from the live numbers (8 assignees, window 10 DAA s today, 25 s proposed, no shard bond, 120-s job claim timeout, S_p 30,000 at v1). Left: O-5.1 and O-5.6 values on the phase 4 devnet |
the founder (values), measurement | before testnet |
| (P14) | P14 | Fixed in spec 05 section 5.1: one controller, the EIP-1559 step of next_base_fee. Left: design 4.1's "smoothed" phrase; R1 band, R8 |
execution engineer | when convenient |
| (F16) | F16 | Two options priced, B recommended (never withdraw, as 3.11.4). Left: replace the 3.5 paragraph, finality_conflict in the node, the forced double-certificate test |
the founder (gate 3), consensus engineer | before testnet |
| 73 | X5 | Measurement defined: N_ind = distinct (ASN, machine fingerprint, pool attestation) classes among keys above dust; today N_ind by fingerprint is 5 for 21 keys. Left: the observer's ASN and fingerprint columns, the pool statement format | Claude (observer), the founder (definition) | before testnet |
| 65 | C4 | The overlay measured against bare GHOSTDAG on the same binary (tools/finality-attacks/c4.mjs): see the ledger entry and the bench-log table |
cryptographer | before testnet |
| 43, 44, 46, 58 | L1 to L5 | Untouched; decision owner line added (the founder, with counsel) | the founder, counsel | as rowed |
| 9 | G3 | Untouched; decision owner line added (the founder) | the founder | now |
3. Overclaims still in public text today
Checked against the files this evening. "present" means the quoted text is still live. "missing" means the item is an addition that has not been made. "fixed" means the replacement is in. Line numbers are from the stripped page text, not the HTML.
| Item | Where | Status | Note |
|---|---|---|---|
| 1 | LP cover | present | |
| 2 | LP abstract | present | |
| 3 | LP abstract | present | |
| 4 | LP firsts intro | present | "six of the pieces are firsts" |
| 5 | LP firsts row | fixed | ProgPoW and KAWPOW named in the adds column |
| 6 | LP firsts row | fixed | now "whose state is proven every block" in substance |
| 7 | LP firsts row | present | "immune to hour-long rentals" |
| 8 | LP firsts row | present | "Kaspa's fair launch, with no utility" |
| 9 | LP firsts row | fixed | phase two stated in the adds column |
| 10 | LP problem | present | "the first chain built so that it can never be taken away again" |
| 11 | LP problem | partly | Ergo and Ravencoin named; "taken over by chips, as Kaspa was" still reads as capture; Conflux missing |
| 12 | LP problem | present | "cheapest supplier" |
| 13 | LP glance | present | |
| 14 | LP mining | present | "bound by memory bandwidth" |
| 15 | LP mining | present | |
| 16 | LP mining | present | rewrite with the cache measurement (row 17), not the ledger's wording |
| 17 | LP mining | present | |
| 18 | LP mining | present | |
| 19 | LP mining | present | |
| 20 | LP vs RandomX | present | rewrite with AMD integrated included (row 18) |
| 21 | LP vs RandomX | present | now largely true: measured 0.41 to 1.2 ms with the cache on one core; say "on one core" |
| 22 | LP vs RandomX | fixed | HP too |
| 23 | LP measured so far | fixed, stale | the cache has landed and was measured on the 5090 and AMD; update the paragraph |
| 24 | LP proving | present | "the one useful GPU workload" |
| 25 | LP proving | present | |
| 26 | LP proving | present | |
| 27 | LP proving | fixed | |
| 28 | LP proving | present | "No other proof-of-work chain has a seat in it" |
| 29 | LP speed | present | "proven on Kaspa" |
| 30 | LP speed | present | replacement must not cite the ledger |
| 31 | LP finality | partly | first-month sentence added; "no amount of fresh hashrate" and the two-thirds clause missing |
| 32 | LP finality | present | |
| 33 | LP finality | missing | pool sentence not added |
| 34 | LP finality | missing | two-hour exposure not added |
| 35 | LP building | present | also the abstract "runs on Igneum unchanged" |
| 36 | LP building | present | |
| 37 | LP building | present | |
| 38 | LP building | fixed | applied 3 October 2026 |
| 39 | LP building | present | "Canto and Blast proved" |
| 40 | LP building | fixed | applied 3 October 2026 with the decided text, not the ledger's replacement |
| 41 | LP builders ask | present | |
| 42 | LP builders ask | present | |
| 43 | LP governance | present | |
| 44 | LP governance | present | |
| 45 | LP governance, HP tile | present | |
| 46 | LP governance | present | must also lose the fund (row 31) |
| 47 | LP miners ask | fixed | |
| 48 | LP miners ask | present | |
| 49 | LP miners ask | present | |
| 50 | LP not claimed | present | |
| 51 | LP not claimed | present | |
| 52 | LP economics | present | |
| 53 | LP economics, governance | present | superseded: no fund; rewrite the whole section (row 7) |
| 54 | LP supply | present | |
| 55 | LP miners | present | |
| 56 | LP miners | present | rewrite with the AMD integrated result (row 18) |
| 57 | HP Mine card | present | "approximate" missing on HP |
| 58 | LP roadmap, J phase 6 | present | both files |
| 59 | HP hero | present | |
| 60 | HP buttons | present | three "Get the miner" plus "Start mining" |
| 61 | HP live panel | present | |
| 62 | HP economics | present | |
| 63 | HP hero, HP Mine card | present | both places |
| 64 | HP hero | present | |
| 65 | HP footer, /bench nav | present | |
| 66 | HP vs RandomX | present | items 20 and 21 present, item 22 fixed |
| 67 | HP vs RandomX | present | |
| 68 | LP and HP heading | present | both |
| 69 | LP roadmap | missing | |
| 70 | LP mining table | present | |
| 71 | LP builders | fixed | heading, the Arbitrum and Base line, "an Ethereum bridge, ship at genesis" and the builders-ask answer, 3 October 2026 |
| 72 | LP cover | missing | the sentence names the method only, never a location |
| 73 | LP who are you | do not apply | the founder is pseudonymous now; use the row 9 text |
| 74 | LP finality | missing | |
| 75 | LP fair launch | partly | Finality has the first-month sentence; the fair-launch paragraph and "exchanges are told" do not |
| 76 | LP supply, chart caption, HP | present | three places |
| 77 | HP and LP | present | no contact route anywhere |
| 78 | LP not claimed | missing | the first of the three items needs the cache result, not "can be shortcut 110x" |
2.4 Round 4 entries (4 October 2026, afternoon)
Added after docs/review/round-4-2026-10-04.md. Rows continue the numbering of section 2. Effort is the review's estimate in hours.
| # | Ledger | Issue | Fix | Who | When | EXPOSES |
|---|---|---|---|---|---|---|
| 104 | X23 | Either relay secret queues administrator PowerShell on the PCs; the intake key is the relay key, is in 6 tracked files and ships in every package; the relay-clients zip with both secrets is hosted behind the dl token | Zip off the host; rotate the relay token; a relay key of its own; a second per-machine secret or a signature for run; rotate the intake key and repackage (2 h) |
the founder (rotation), relay owner | now | EXPOSES: the PCs are the founder's own machines |
| 105 | G13 | The OTA manifest is signed over an installer whose node and worker binaries arrived unsigned from the dl host; signing is automatic from the latest green run | Sign payload-inputs.zip on the Mac, verify in CI; OTA_SKIP=1 by default, the signing step names the run (2 h) |
release engineer | now | no |
| 106 | G12, X18 | IGNEUM_POW_* sets the schedule on every network; no params digest or genesis hash in the handshake; a finality mismatch is a WARN; rollout-v2.sh drops the finality block |
Delete the fallback; digest plus genesis hash in the version message, refused on mismatch; the WARN becomes a refusal (4 h) | consensus engineer (code) | before testnet | no |
| 107 | F23, F24 | Node-local equivocation ban time; checkpoint determination never revisited | Carrier-DAA bans; re-determine on a reorg deeper than d; two-node tests (4 h) | consensus engineer, cryptographer (code) | before testnet | no |
| 108 | M26, M27, X21 | Frozen fault-guard baseline loops; no prepare rate limit; mismatches never acted on and invisible in the app | Baseline updated on a trip; one prepare per pair per epoch; stop at 3 mismatches, shown on the card (3 h) | miner-community-lead, app owner (code) | now | no |
| 109 | E16 | The 20% pool is an OP_RETURN on the live chain; LP 396 and 414, HP 306 and 446 say it pays provers | "Burned until the payout ships; no prover is paid today" in both places; burned-so-far on the live page | Claude | now | no |
| 110 | L9 | HP "100% to miners and provers", "0% anyone else"; no devnet-value statement beside Get the miner or on the live page | The disclaimer beside the button and on /live; the tiles match the LP dev-fee sentence | Claude | now | no |
| 111 | M29 | LP 424 describes earnings in currency, a hardware wallet and proving the app does not have | Rewrite to 0.3.3; earnings, currency and the hardware wallet become a roadmap sentence | Claude | now | no |
| 112 | F21 | LP 511 says a third of the blocks is needed to split finality in a partition | The round-4 section 1 (b) sentence | Claude | now | no |
| 113 | X24, X25, X26, X27 | Token in the URL path and printed; agent self-installs at every start; permanent feed with the dl token in bodies; free-text from and no clean rotation |
Header token in every client, HSTS, masked prints; arm only on reboot_continue; retention and a cap; sender binding; documented rotation (3 h) |
relay owner | now | no |
| 114 | G14 | The intake key (8 commits), the dl token (1), the review files, 51 files with the first name, local-time stamps | Section 5 step 4's rewrite list extended; TZ=UTC now |
the founder, Claude | before public repo | EXPOSES: yes, the whole row |
| 115 | X19, X20, M25, M28, X22, X28, X29, E17 | The minors of round 4 (node knobs and silences, cold-sync cost, miner day length, kernel commitment, restart paths, relay hygiene, host and file modes, unlogged economics inputs) | As each ledger entry says; the stray token-named file and the 0644 modes today | consensus engineer, miner-community-lead, relay owner, Claude | when convenient | no |
| 116 | X30 | Bench page private strings; /api/live addresses, key hashes, payout addresses; the mobile menu | Fixed 4 October 2026: ac89a37, 6b644a6, 2d8f09c, 621f5cc |
Claude | done | no |
2.5 Ledger sweep (night of 4 to 5 October 2026)
Added by docs/review/ledger-sweep-2026-10-05.md, which holds what ran, what did not and why. Rows continue the numbering. Effort in hours. Items owned by the fud-consensus branch (F23, F24, G12, X18, the flood memory growth) and the testnet-prep branch (the base-fee floor, testnet parameters, G13, G14, public text) are not repeated here.
| # | Ledger | Issue | Fix | Who | When | EXPOSES |
|---|---|---|---|---|---|---|
| 117 | M20 | Pruning-proof headers are still checked with the kHeavyHash stub on devnet-v4 (pruning_proof/validate.rs:192, apply.rs:74, 200, mod.rs:207), and validate_trusted_header skips pre_pow_validation (round 4) |
Derive the epoch and day of a proof header from the proof's own headers (fork map a4, O-2.5), replace the stub call, run the bits and DAA checks on trusted headers; test: a fresh node syncs a fast-time simnet past its pruning depth (6 h) | consensus engineer | before testnet | no |
| 118 | X20 | Cold sync walks the selected chain once per checkpoint index from index 1 (processes/finality.rs:204) |
Start from the last certified index carried in headers and walk once; test on a 10^5-block fast-time simnet, time to first resolution (2 h) | consensus engineer | before testnet | no |
| 119 | P15 | The RPC block's gasLimit is one block's B_e beside a segment's summed gasUsed (proving branch, igneum/exec/src/rpc.rs:355-356) |
Report k x B_e for a k-block segment, or document the invariant break for Blockscout (R10) (1 h) |
execution engineer | before a public RPC | no |
| 120 | M28 | Nothing commits the seed to the kernel text the worker compiles; no kernel hash exists on any branch | A hash of the emitted kernel in program.json, derived from the seed by the miner and checked by both workers; one sentence in the docs that the chain commits to the seed, not the text (3 h) |
miner lead | before testnet | no |
| 121 | M21 | k = 18 is Kaspa's table value; calculate_ghostdag_k gives k 5 at the cloud devnet's measured p99 of 0.67 s and k 55 at a 20-s bound, and proof-bearing bodies are unmeasured |
Run O-2.2 with bodies of the size design 5.4 implies, take the p99 propagation, re-derive k with the fork's function (the table is in the ledger entry) (3 h) | consensus engineer | before testnet | no |
| 122 | X29 | The live node's gRPC listens on every interface (igneumd on *:26610, read-only check 5 October); the file modes are fixed |
--rpclisten=127.0.0.1:26610; PC 2 through a tunnel or its own node (0.5 h) |
app owner, the founder | now | no |
| 123 | M14, F14 | O-3.14 (the finality simulation with the DAA in the loop under both forms of W2) has no DAA model inside finality_v2.py; the chain-model result (no amplification under either controller) stands in for it |
Add a lagging retarget to finality_v2.py (Kaspa's sampled window and rule v2), run the 50x pulse under both W2 forms, log the day the renter crosses a third (4 h) |
cryptographer (sim) | before testnet | no |
| 124 | F1, O-3.1 | Spec 06 row O-3.1 still said "not yet in sim/" and the ledger's launch-month arithmetic was in prose only |
Done in the sweep (5 October 2026): rows O-3.1, O-3.14, O-5.9 and O-5.11 of spec 06 carry tonight's evidence (O-3.15 was already marked decided) | Claude (spec) | done | no |
| 125 | X14 | Only hashing concentration can be computed from what the observer keeps; signing, proving and aggregation need certificate and proof-record extracts | The observer stores signer bitmaps per certificate and prover keys per proof record; a nightly top-1/3/10 table on the live page (3 h) | app owner (observer) | before testnet | no |
| 126 | E12 | The devnet half of O-5.9 (profit-only prover clients, f_p and B_p paths) |
Phase 4 devnet run as the ledger entry states (4 h) | execution engineer | before testnet | no |
| 127 | M25 | Confirmed 5 October 2026 (sweep batch 3): a miner started with a different IGNEUM_POW_DAY_MS builds its cache for another day and every block is rejected as BlockInvalid / block has invalid proof-of-work, with no line naming the day (0 of 4 accepted against 7 of 7 for the control) |
The day length (or the day index) in the template beside pow_epoch, the miner takes it from there and ignores the environment; the node's PoW rejection names the engine's day and the header's day (1.5 h) |
miner lead, consensus engineer | before testnet | no |
2.7 Close round 1 (5 October 2026, night)
Appended by the public-text closer (worktree igneum-wt-ledger-text, branch ledger-text, group A of docs/plans/ledger-close-plan.md). Every sentence named here was grepped in the public text before the ledger row moved. Rows name the earlier row they touch; nothing above is rewritten.
| Row touched | Ledger | What changed (5 October 2026, night) | Who next | When |
|---|---|---|---|---|
| 17, 48, 53, 56, 15 | M2, M4, M7, M9, M10 | Verified and moved to "Conceded, stated" (M10: "Answered with evidence, stated"). M10's overclaim 14 was still live at 18:20 UTC and is applied now: "bound by random memory access", 95 GB/s of useful loads against 1,638 GB/s sequential, RTX 5090 | none | done |
| 19 | M13 | "a fifth" confirmed in For miners, Hardware (26.7 against 123 MH/s, 4 October 2026); moved | none | done |
| 10, 11 | F5, F10 | Verified and moved | none | done |
| 57, 21, 22, 24, 25, 26 | P1, P3, P4, P6, P7, P10 | Verified and moved. P3: overclaim 25 applied ("Wrapped for light clients ... phase two measurement") with the certificate-half numbers of bench-log round 6 (139 to 155 ms cold, 58 to 68 ms warm, laptop core, no phone); the wrapper stays Open for phase two | measurement (the wrapper) | before public repo |
| 8, 27 | E5, E6 | E5 verified and moved. E6: one sentence in Security after the subsidy, "The schedule is a bet, not a measurement", Kaspa's reduction marked approximate; moved | none | done |
| 28, 29, 9, 30, 32 | G1, G2, G3, G4, G6 | Verified and moved. G3: the entry's first Status line is now the Decided line (no team page; "The team is pseudonymous and there is no team page" in the litepaper), the older line kept prefixed "Was:" | none | done |
| 14, 12, 13, 34, 49 | C2, C3, C5, C6, C8, C10, C11 | Verified and moved | none | done |
| (C13, M18, L8) | C13, M18, L8 | C13: "they say nothing about the price of a chip with the 256 MB cache on its die" in What Igneum does not claim. M18 verified. L8: "whether it is issued is Circle's decision" in Questions builders ask; Canto and Blast absent. All moved | none | done |
| 6 | L2 (text half) | "so the people who show up early get the most" removed from Supply; schedule fact only. Counsel half unchanged, decision owner the founder | the founder, counsel | before public repo |
| 110 | L9 | "Devnet: coins have no value and the chain may be reset." beside every download control on index, miner and wallet; the homepage tiles read "of emission to miners and provers; the protocol carries no fee" and "0% anyone else in the protocol". Not done: the same line on /live (outside this round's files) |
Claude (live page) | now |
| 111 | M29 | The litepaper's app paragraph rewritten to Ember 0.3.9 from the shipped UI; earnings, currency, game pause and the hardware wallet moved to a roadmap sentence; nothing from an unmerged branch | none | done |
| 109 | E16 (text half) | The 20% row and the homepage bar now say the coinbase's 20% output is burned under igneum-proving-pool-v0 and provers are paid from the execution-state escrow credited with the same 20%; the single coinbase payout stays Open (code half, group D) |
consensus engineer (payout) | before testnet |
| 115 | E17 (text half) | "a million 100,000-gas calls a day" with the base unit marked Open; the fleet-size dependence sentence (4.9x today, 930x at 10,000 cards, approximate). Draw lines still owed | measurement (draw lines) | when convenient |
| 94 | E13 | The six-row route table in the litepaper Economics ("Every payment route") and in the customer brief; source docs/design/payment-routes.md; moved to "Conceded, stated". That file's section 4 states are of 3 October and now lag the litepaper |
Claude (refresh payment-routes.md section 4) | when convenient |
| 1, 2, 39, 3, 4 | X1, X2, X3, X7, X8 | Verified and moved. X3: "Live rows arrive with the public testnet, August 2027" under the proofs feed (overclaim 61); the old sentence was already gone. X7 closes on the ledger's submission line (hello@igneum.network, spec issues) | none | done |
| 36, 5 | X9, X10, D2 | Verified and moved; D2's sentence now reads "100,000-gas calls" (E17) | none | done |
4. What the 3 October decisions close or change
Closed:
- E4 (5% of gas is a tax): closed by (a). There is no fund and no 5%.
- G8, the 60% half: narrowed by (a). The 60% spend vote no longer exists; CLAUDE.md keeps 60% signalling only for parameters genesis leaves to miners. The 90% upgrade signal and the pool-concentration risk remain.
- O-5.4, the fund-contract half: closed by (a). Genesis contract and bridge key policies remain (row 74).
- L3, the nameserver half: closed by (d) once the deSEC cut-over completes. The registrar half closes in December 2026. The host, the mirror and the seed-node rule remain (row 44).
- X7, the ledger submission route: moot by (b). A contact route for the litepaper is still needed (row 3).
- Overclaim 30's cross-reference to the ledger: dropped by (b). Overclaim 53 and the fund half of 46: superseded by (a), rewrite instead of applying.
Closed on the evening of 3 October 2026 (written into docs/spec/ the same evening):
- F2: the quorum floor of rule v2 is the answer to the eclipse case (spec 3.3.2). O-3.7 is confirmation only.
- F3: participation from every vote seen in blocks, votes are block payload (spec 3.3 Q2, 3.4.1). O-3.3 keeps the parameter.
- P5: EVM semantics on the DAG (spec 7.1). O-2.8 removed.
- P8 and C9: shard sortition, 8 provers, 10 s, then open, no shard bond (spec 7.2). O-5.1 keeps the measurement; O-5.6 is the job bond only.
- E7: no bridged stablecoins at genesis, no official bridge, proof bridge in phase two (spec 7.3). Overclaims 38, 40 and 71 applied; O-5.2 keeps the settlement switch.
- G7 and X6: client security policy (spec 08). The permanent line is on HP and LP. O-8.1 is the key custody policy.
- The ledger's Count by status table and the eight Status lines were updated by the same commit.
Changed, not closed:
- E3 (wash gas): under 80/20 a developer alone gets 20% of its own tip back and loses 80%. A developer who also mines the block gets 80% plus 20%, less the provers' part of the 80%. The only certain loss is the base fee. The ledger's "guaranteed loss of 20% of the tip plus the base fee" no longer holds. The founder confirms the 15% priority-fee burn is gone on purpose; if not, the split is 80/20 of what remains after a burn and the numbers in row 7 change.
- E5 (dev fee to the founder's company): the ledger says the company carries development "until usage funds the development fund". There is no fund, so the company carries it for as long as the 1% fee, the pool and the proving business pay. That is the sentence the litepaper must carry, and it sharpens L1.
- G5 (second client): "funded from the development fund as its first priority" has no funder. Row 47.
- G3 (who are you): the anonymous founder is now the design, not a flaw to rebut. The ledger's "The founder's name is on every commit" is void. Row 9. The team-page-at-testnet decision needs re-confirming.
- L1 and L2 (counsel): "offshore, parked" and "jurisdiction not yet named" become "offshore, being established", which is a jurisdiction counsel can be briefed in. Not closed until the opinion exists.
- The ledger header ("Published alongside the litepaper") and its submission paragraph are now wrong under (b). Both lines were rewritten on 5 October 2026 under the later decision: published with the repository at the public testnet, submissions to hello@igneum.network or the repository issues.
- Decision (e) makes CLAUDE.md stale: it still says the Vercel project lives in the other business's team (moved per commit 61aa946) and lists two organisation owners. Section 5 step 2.
Text the decisions force, beyond the overclaims list: row 7 lists every file. The design document is the eleventh place and the only one outside the repository.
5. Before the repository goes public, in order
The repository goes public at the public testnet (decision of 5 October 2026). The ledger and this file are published with it.
Nothing below is optional. The history, not just the working tree, carries the names: CLAUDE.md with the full name is in every commit, the ledger's earlier L2 text ("The founder is in the UK") is in the commits before 14ef6b3, and site/ledger.html (636 lines, the full ledger rendered) is in the commits before the same one. The commit author and committer on every commit is igneum-labs, and every commit carries a local-time offset one hour ahead of UTC, which is UK or Irish summer time in early October. A file edit fixes none of that.
- Keep the ledger in the tree and publish it with the repository (decision of 5 October 2026, which replaces decision b).
docs/fud-ledger.mdand this file (docs/fud-fixes.md) are on the public export list oftools/ci/identity-check.sh; every hit the check finds in them is reworded before the first public push, and no entry is removed. The ledger still maps the providers (GoDaddy, Vercel) and names.claude/agents/; the private export rules cover the founder's name, and the rest is reworded in place. The spec and the open-items file cite ledger ids (M7, F1, P8 and so on); those ids do not change. - Rewrite CLAUDE.md as a public file. Remove: line 4 ("the founder's project"); every "the founder" (lines 22, 34, 39, 41, 46, 48, 52; "the founder's copy law" becomes "the copy law"); line 42 (the second owner the second owner login, "the founder, the igneum.network Google login", the sentence about 40 commits carrying his name); line 43 (other business's team; it is the igneum team now); line 44 (Neon id and London region); lines 46 to 49 (registrar, "Full Protection", the purchase quotes; after December the registrar changes anyway); lines 51 to 53 (the browser-profile section names every other business: the other business, QUANTUM, the earlier entity, the earlier business, another brand, another brand); the claude.ai artifact and doc links in "Source of truth" (they identify the tooling account). Move the operational notes (accounts, registrar, database id, browser profile, deploy scope) to a file outside the repository, for example
~/.config/igneum/NOTES.md. - Scrub
.claude/agents/cryptographer.mdline 32 ("unless the founder overrides" becomes "unless the project lead overrides"). The other three agent files are clean. Decide whether.claude/agents/stays public at all; if it does, it is the G2 disclosure and consistent with row 29. - Rewrite the history once, before the first public push. Nothing is public and nobody has cloned, so the cheapest safe route is to squash to one root commit ("Igneum: public tree") authored by a neutral handle at a UTC timestamp. If the history is kept instead, run git filter-repo to: drop
site/ledger.htmlfrom every commit; replace CLAUDE.md, the agent file,docs/fud-ledger.mdanddocs/fud-fixes.mdin every commit with the scrubbed versions; rewrite every author and committer to the neutral handle; rewrite every date to +0000. Either way: rename the GitHub account igneum-labs to a handle without a name (the noreply address keeps its numeric id, so the rename is one setting), confirm the second owner login is no longer an organisation owner (decision e says one anonymous owner), and setTZ=UTCin whatever script commits from now on so no local-time offset appears again. - Check the organisation and the account profiles: no location, no personal avatar, no personal email, 2FA on, the organisation's public members list empty. The Vercel team igneum and the Workspace are not visible from the repository; nothing to do there beyond step 2.
- Add a LICENSE and a root README. Neither exists (
git ls-filesshows no root README or LICENSE). A public repository without a licence invites the first issue to be about the licence. The founder picks the licence. - Re-run the sweep from this evening on the final tree:
git ls-files | xargs grep -nIE -f igneum-public/tools/identity.local(the private identity list, case-insensitive) must return nothing, andgit log --format='%an %ae %cn %ce %ad'must show one neutral identity and +0000 only. Secrets: the history grep for connection strings and tokens returned zero hits today; repeat it after the rewrite. - Fix the public text first (rows 1 to 41). The ledger's X1 answer is that the honest route is to open the repository with the bench logs, the simulator and the test report. Opening it with "no chip can ever" still on the homepage hands the first critic the ledger's own list.
- Put the GitHub links back on HP and the /bench page (row 1) on the day the repository opens, at the public testnet.
What is already clean: docs/bench-log.md and the /bench page name machines, not people (commit 1769eda); the live site returns 404 for everything under docs/ and 307 for /ledger; site/.env.local, site/.vercel/ and vendor/ are ignored; no tracked file carries a home-directory path; no connection string or token appears anywhere in the history.
| 128 | P23 | The EVM pool has on_chain_block and no reorg hook, so a transaction unwound by a selected-chain reorg leaves the node until its sender resends (found by the P17 conformance run, 6 October 2026) | A reorg hook: unwound transactions handed back to the pool as pending with the usual checks; unit test; the conformance driver's reorged out case ends in executed without a resend (2 h) | execution engineer (round 3 ledger-rebase carries it) | before a public RPC | no |